<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: More malware from ircer.pl</title>
	<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/</link>
	<description>About malware, packers and reverse engineering</description>
	<pubDate>Fri, 21 Nov 2008 07:18:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: MAD</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-103</link>
		<dc:creator>MAD</dc:creator>
		<pubDate>Sat, 26 May 2007 03:39:45 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-103</guid>
		<description>A new release, 8 May 2007 GTM+1, dropper file is download via website, the files are now packed with PEC2.

Source: http://secubox.aldria.com/topic-post1867.html

______________________________________________________________
.text &#62;&#62; 0000a228 ( 1000a228 ) &#62;&#62; SeDebugPrivilege
.text &#62;&#62; 0000a23c ( 1000a23c ) &#62;&#62; explorer.exe
.text &#62;&#62; 0000a24c ( 1000a24c ) &#62;&#62; WINLOGON.EXE
.text &#62;&#62; 0000a25c ( 1000a25c ) &#62;&#62; rundll32.exe
.text &#62;&#62; 0000a270 ( 1000a270 ) &#62;&#62; SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings
.text &#62;&#62; 0000a2b4 ( 1000a2b4 ) &#62;&#62; Time
.text &#62;&#62; 0000a2bc ( 1000a2bc ) &#62;&#62; g_InstallPath
.text &#62;&#62; 0000a2cc ( 1000a2cc ) &#62;&#62; g_InstallDLL
.text &#62;&#62; 0000a2dc ( 1000a2dc ) &#62;&#62; xWovqdo
.text &#62;&#62; 0000a2e4 ( 1000a2e4 ) &#62;&#62; Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
.text &#62;&#62; 0000a324 ( 1000a324 ) &#62;&#62; Logon
.text &#62;&#62; 0000a32c ( 1000a32c ) &#62;&#62; Logoff
.text &#62;&#62; 0000a338 ( 1000a338 ) &#62;&#62; SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
.text &#62;&#62; 0000a380 ( 1000a380 ) &#62;&#62; SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
.text &#62;&#62; 0000a3cc ( 1000a3cc ) &#62;&#62; SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
.text &#62;&#62; 0000a3fc ( 1000a3fc ) &#62;&#62; MSServer
.text &#62;&#62; 0000a408 ( 1000a408 ) &#62;&#62; CLSID\
.text &#62;&#62; 0000a410 ( 1000a410 ) &#62;&#62; Asynchronous
.text &#62;&#62; 0000a420 ( 1000a420 ) &#62;&#62; DllName
.text &#62;&#62; 0000a428 ( 1000a428 ) &#62;&#62; Impersonate
.text &#62;&#62; 0000a434 ( 1000a434 ) &#62;&#62; Logon
.text &#62;&#62; 0000a43c ( 1000a43c ) &#62;&#62; Logoff
.text &#62;&#62; 0000a448 ( 1000a448 ) &#62;&#62; awx_mutant
.text &#62;&#62; 0000a454 ( 1000a454 ) &#62;&#62; AD-AWARE.EXE
.text &#62;&#62; 0000a464 ( 1000a464 ) &#62;&#62; %08x
.text &#62;&#62; 0000a470 ( 1000a470 ) &#62;&#62; Kernel32
.text &#62;&#62; 0000a47c ( 1000a47c ) &#62;&#62; LoadLibraryA
.text &#62;&#62; 0000a48c ( 1000a48c ) &#62;&#62; PSAPI.dll
.text &#62;&#62; 0000a498 ( 1000a498 ) &#62;&#62; EnumProcessModules
.text &#62;&#62; 0000a4ac ( 1000a4ac ) &#62;&#62; GetModuleFileNameExA
.text &#62;&#62; 0000a4c4 ( 1000a4c4 ) &#62;&#62; psapi.dll
.text &#62;&#62; 0000a4d0 ( 1000a4d0 ) &#62;&#62; %s\tmp%08x
.text &#62;&#62; 0000a4dc ( 1000a4dc ) &#62;&#62; rundll32.exe %s,Activate
.text &#62;&#62; 0000a4f8 ( 1000a4f8 ) &#62;&#62; HookProc
.text &#62;&#62; 0000a504 ( 1000a504 ) &#62;&#62; %s\%s
.text &#62;&#62; 0000b620 ( 1000b620 ) &#62;&#62; http://65.243.103.80/80
.text &#62;&#62; 0000b638 ( 1000b638 ) &#62;&#62; SOFTWARE\Microsoft\Installer
.text &#62;&#62; 0000b65c ( 1000b65c ) &#62;&#62; Identities
.text &#62;&#62; 0000b668 ( 1000b668 ) &#62;&#62; URLDownloadToFileA
.text &#62;&#62; 0000b67c ( 1000b67c ) &#62;&#62; urlmon.dll
.text &#62;&#62; 0000b690 ( 1000b690 ) &#62;&#62; uid=
.text &#62;&#62; 0000b698 ( 1000b698 ) &#62;&#62; %s/%s
.text &#62;&#62; 0000b6a8 ( 1000b6a8 ) &#62;&#62; SOFTWARE\Microsoft\zxc5
.text &#62;&#62; 0000b6c0 ( 1000b6c0 ) &#62;&#62; 0123456789ABCDEFopen
.text &#62;&#62; 0000b6dc ( 1000b6dc ) &#62;&#62; ShellExecuteA
.text &#62;&#62; 0000b6ec ( 1000b6ec ) &#62;&#62; shell32.dll
.text &#62;&#62; 0000b700 ( 1000b700 ) &#62;&#62; %s/%s?i=%s&#38;v=%x_%x_%x_%x_%s&#38;g=%s&#38;t=%04i_%02i_%02i_%02i_%02i&#38;d=%i%s&#38;a=%i
.text &#62;&#62; 0000b748 ( 1000b748 ) &#62;&#62; &#38;s=1
.text &#62;&#62; 0000b750 ( 1000b750 ) &#62;&#62; &#38;m=1
.text &#62;&#62; 0000b758 ( 1000b758 ) &#62;&#62; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
______________________________________________________________

Regards,</description>
		<content:encoded><![CDATA[<p>A new release, 8 May 2007 GTM+1, dropper file is download via website, the files are now packed with PEC2.</p>
<p>Source: <a href="http://secubox.aldria.com/topic-post1867.html" rel="nofollow">http://secubox.aldria.com/topic-post1867.html</a></p>
<p>______________________________________________________________<br />
.text &gt;&gt; 0000a228 ( 1000a228 ) &gt;&gt; SeDebugPrivilege<br />
.text &gt;&gt; 0000a23c ( 1000a23c ) &gt;&gt; explorer.exe<br />
.text &gt;&gt; 0000a24c ( 1000a24c ) &gt;&gt; WINLOGON.EXE<br />
.text &gt;&gt; 0000a25c ( 1000a25c ) &gt;&gt; rundll32.exe<br />
.text &gt;&gt; 0000a270 ( 1000a270 ) &gt;&gt; SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Settings<br />
.text &gt;&gt; 0000a2b4 ( 1000a2b4 ) &gt;&gt; Time<br />
.text &gt;&gt; 0000a2bc ( 1000a2bc ) &gt;&gt; g_InstallPath<br />
.text &gt;&gt; 0000a2cc ( 1000a2cc ) &gt;&gt; g_InstallDLL<br />
.text &gt;&gt; 0000a2dc ( 1000a2dc ) &gt;&gt; xWovqdo<br />
.text &gt;&gt; 0000a2e4 ( 1000a2e4 ) &gt;&gt; Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<br />
.text &gt;&gt; 0000a324 ( 1000a324 ) &gt;&gt; Logon<br />
.text &gt;&gt; 0000a32c ( 1000a32c ) &gt;&gt; Logoff<br />
.text &gt;&gt; 0000a338 ( 1000a338 ) &gt;&gt; SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks<br />
.text &gt;&gt; 0000a380 ( 1000a380 ) &gt;&gt; SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\<br />
.text &gt;&gt; 0000a3cc ( 1000a3cc ) &gt;&gt; SOFTWARE\Microsoft\Windows\CurrentVersion\Run\<br />
.text &gt;&gt; 0000a3fc ( 1000a3fc ) &gt;&gt; MSServer<br />
.text &gt;&gt; 0000a408 ( 1000a408 ) &gt;&gt; CLSID\<br />
.text &gt;&gt; 0000a410 ( 1000a410 ) &gt;&gt; Asynchronous<br />
.text &gt;&gt; 0000a420 ( 1000a420 ) &gt;&gt; DllName<br />
.text &gt;&gt; 0000a428 ( 1000a428 ) &gt;&gt; Impersonate<br />
.text &gt;&gt; 0000a434 ( 1000a434 ) &gt;&gt; Logon<br />
.text &gt;&gt; 0000a43c ( 1000a43c ) &gt;&gt; Logoff<br />
.text &gt;&gt; 0000a448 ( 1000a448 ) &gt;&gt; awx_mutant<br />
.text &gt;&gt; 0000a454 ( 1000a454 ) &gt;&gt; AD-AWARE.EXE<br />
.text &gt;&gt; 0000a464 ( 1000a464 ) &gt;&gt; %08x<br />
.text &gt;&gt; 0000a470 ( 1000a470 ) &gt;&gt; Kernel32<br />
.text &gt;&gt; 0000a47c ( 1000a47c ) &gt;&gt; LoadLibraryA<br />
.text &gt;&gt; 0000a48c ( 1000a48c ) &gt;&gt; PSAPI.dll<br />
.text &gt;&gt; 0000a498 ( 1000a498 ) &gt;&gt; EnumProcessModules<br />
.text &gt;&gt; 0000a4ac ( 1000a4ac ) &gt;&gt; GetModuleFileNameExA<br />
.text &gt;&gt; 0000a4c4 ( 1000a4c4 ) &gt;&gt; psapi.dll<br />
.text &gt;&gt; 0000a4d0 ( 1000a4d0 ) &gt;&gt; %s\tmp%08x<br />
.text &gt;&gt; 0000a4dc ( 1000a4dc ) &gt;&gt; rundll32.exe %s,Activate<br />
.text &gt;&gt; 0000a4f8 ( 1000a4f8 ) &gt;&gt; HookProc<br />
.text &gt;&gt; 0000a504 ( 1000a504 ) &gt;&gt; %s\%s<br />
.text &gt;&gt; 0000b620 ( 1000b620 ) &gt;&gt; <a href="http://65.243.103.80/80" rel="nofollow">http://65.243.103.80/80</a><br />
.text &gt;&gt; 0000b638 ( 1000b638 ) &gt;&gt; SOFTWARE\Microsoft\Installer<br />
.text &gt;&gt; 0000b65c ( 1000b65c ) &gt;&gt; Identities<br />
.text &gt;&gt; 0000b668 ( 1000b668 ) &gt;&gt; URLDownloadToFileA<br />
.text &gt;&gt; 0000b67c ( 1000b67c ) &gt;&gt; urlmon.dll<br />
.text &gt;&gt; 0000b690 ( 1000b690 ) &gt;&gt; uid=<br />
.text &gt;&gt; 0000b698 ( 1000b698 ) &gt;&gt; %s/%s<br />
.text &gt;&gt; 0000b6a8 ( 1000b6a8 ) &gt;&gt; SOFTWARE\Microsoft\zxc5<br />
.text &gt;&gt; 0000b6c0 ( 1000b6c0 ) &gt;&gt; 0123456789ABCDEFopen<br />
.text &gt;&gt; 0000b6dc ( 1000b6dc ) &gt;&gt; ShellExecuteA<br />
.text &gt;&gt; 0000b6ec ( 1000b6ec ) &gt;&gt; shell32.dll<br />
.text &gt;&gt; 0000b700 ( 1000b700 ) &gt;&gt; %s/%s?i=%s&amp;v=%x_%x_%x_%x_%s&amp;g=%s&amp;t=%04i_%02i_%02i_%02i_%02i&amp;d=%i%s&amp;a=%i<br />
.text &gt;&gt; 0000b748 ( 1000b748 ) &gt;&gt; &amp;s=1<br />
.text &gt;&gt; 0000b750 ( 1000b750 ) &gt;&gt; &amp;m=1<br />
.text &gt;&gt; 0000b758 ( 1000b758 ) &gt;&gt; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)<br />
______________________________________________________________</p>
<p>Regards,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-45</link>
		<dc:creator>toni</dc:creator>
		<pubDate>Mon, 30 Apr 2007 14:35:16 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-45</guid>
		<description>Glad the entry was of help. I'm not aware of all the ways they can push that malware to victims. You might want to check for any suspicious connections on your computer. Some of the DNS names they've used are:
zief.pl
proxima.ircgalaxy.pl

The botnet C&#38;C has usually been at port 65520.</description>
		<content:encoded><![CDATA[<p>Glad the entry was of help. I&#8217;m not aware of all the ways they can push that malware to victims. You might want to check for any suspicious connections on your computer. Some of the DNS names they&#8217;ve used are:<br />
zief.pl<br />
proxima.ircgalaxy.pl</p>
<p>The botnet C&amp;C has usually been at port 65520.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-44</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Mon, 30 Apr 2007 13:33:43 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-44</guid>
		<description>Thanks. This IP address just flashed up on my firewall. AVG &#38; Windows Defender don't pick up the dll as anything bad, but I found the offending dll (mine was called ssqromk.dll) and entries in the registry (winlogon notify) and clsid {4FFADED8-CE19-4FC5-9547-7881FDB5D120}. Registered as a Browser Help object quickly picked up in Ace Utilities.</description>
		<content:encoded><![CDATA[<p>Thanks. This IP address just flashed up on my firewall. AVG &amp; Windows Defender don&#8217;t pick up the dll as anything bad, but I found the offending dll (mine was called ssqromk.dll) and entries in the registry (winlogon notify) and clsid {4FFADED8-CE19-4FC5-9547-7881FDB5D120}. Registered as a Browser Help object quickly picked up in Ace Utilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heavy</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-29</link>
		<dc:creator>Heavy</dc:creator>
		<pubDate>Mon, 23 Apr 2007 22:18:27 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-29</guid>
		<description>the file can contains more then 5 random digits... this is bull shit has some stupid modifications... for example, in my system it was ddcdaay.dll ... i remove it under system self mode, after dissalow permitions to write anybody to this registry path (like dll name) -- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcdaay</description>
		<content:encoded><![CDATA[<p>the file can contains more then 5 random digits&#8230; this is bull shit has some stupid modifications&#8230; for example, in my system it was ddcdaay.dll &#8230; i remove it under system self mode, after dissalow permitions to write anybody to this registry path (like dll name) &#8212; HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcdaay</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Toni</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-23</link>
		<dc:creator>Toni</dc:creator>
		<pubDate>Sat, 21 Apr 2007 06:49:12 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-23</guid>
		<description>The files are dropped into the sysdir (C:\windows\system32 for most systems) under a 5 digit random character filename ending in .dll</description>
		<content:encoded><![CDATA[<p>The files are dropped into the sysdir (C:\windows\system32 for most systems) under a 5 digit random character filename ending in .dll</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rod</title>
		<link>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-21</link>
		<dc:creator>Rod</dc:creator>
		<pubDate>Thu, 19 Apr 2007 20:12:23 +0000</pubDate>
		<guid>http://www.teamfurry.com/wordpress/2007/03/31/more-malware-from-ircerpl/#comment-21</guid>
		<description>I just found a cookie on my machine referencing 65.243.103.80

Any names available yet as to the files it drops?</description>
		<content:encoded><![CDATA[<p>I just found a cookie on my machine referencing 65.243.103.80</p>
<p>Any names available yet as to the files it drops?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
